CSIDB logo
Incident

Galilee agricultural water pump organization

Incident posture

Attack window
Jun 2020
Location
Israel
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
Galilee agricultural water pump organization
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Cyber-attacks targeted agricultural water drainage installations in two regions, causing no damage as local repairs swiftly addressed issues. The incidents followed an earlier intrusion where hackers attempted to manipulate chlorine levels in treatment systems, potentially endangering public health if successful. Officials linked the initial attack to a foreign state actor, prompting password security directives for operational systems. These events occurred amidst heightened cyber tensions between nations, with reciprocal incidents affecting critical infrastructure.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

3 techniques

Description

In June 2020, two cyber-attacks targeted Israel's water infrastructure, with the first incident impacting agricultural water pumps in the Upper Galilee region. Local media reported the attack occurred alongside a second intrusion targeting water pumps in the Mateh Yehuda central province. Israeli authorities confirmed both June incidents caused no operational damage, characterizing the affected systems as small-scale agricultural drainage installations. The Water Authority stated local operators promptly repaired the compromised pumps independently, preventing harm or real-world consequences. Officials did not disclose technical specifics of the attacks but emphasized their limited scope compared to an earlier April 2020 intrusion.

These June incidents followed a more severe April 2020 cyber-attack on Israeli water treatment facilities, initially downplayed but later confirmed by Western intelligence sources to have involved unauthorized access attempts to manipulate water chlorine levels. Had attackers succeeded in altering chemical balances, mild poisoning of local populations could have occurred. In response to the April breach, the Israel National Cyber-Directorate and Water Authority issued alerts mandating password changes for internet-connected operational systems, particularly chlorine control devices. While Israel did not formally attribute the April attack, U.S. media cited intelligence officials linking it to Iran. Geopolitical tensions escalated subsequently, with a May 2020 cyber-attack disabling Iran's Shahid Rajaei port—attributed by U.S. sources to Israel—followed by unexplained explosions and accidents at Iranian petrochemical plants, power facilities, and nuclear sites throughout mid-2020. The water system intrusions marked a visible escalation in cross-border cyber operations between the two nations during this period.

Sources

Sources available to members: 1 source.

CSIDB